Skip to content

[1.4.x] builder-module: Abort on invalid module names - #786

Merged
bbhtt merged 1 commit into
flatpak-builder-1.4.xfrom
bbhtt/backport-715
Sep 15, 2026
Merged

bbhtt merged 1 commit into
flatpak-builder-1.4.xfrom
bbhtt/backport-715

Conversation

@bbhtt

@bbhtt bbhtt commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator

Backports: #715

This goes a step above 6d1d972 and
makes it an actual error. The name is used to construct paths in
various places
@bbhtt

bbhtt commented Sep 15, 2026

Copy link
Copy Markdown
Collaborator Author

do we need a report for the formalities?

@bbhtt bbhtt closed this Sep 15, 2026
@bbhtt bbhtt reopened this Sep 15, 2026
@bbhtt
bbhtt merged commit 17f328f into flatpak-builder-1.4.x Sep 15, 2026
12 checks passed
@bbhtt
bbhtt deleted the bbhtt/backport-715 branch September 15, 2026 23:45
@bbhtt

bbhtt commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator Author

do we need a report for the formalities?

ping @swick

@swick

swick commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator

Probably not a bad idea, I think this might already have a CVE assigned even?

@bbhtt

bbhtt commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator Author

I'm not sure which is it, I don't have the report I think.

@swick

swick commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator

Never mind, only a RH internal ticket exists for this.

@smcv

smcv commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

I don't see anything in https://github.com/flatpak/flatpak-builder/security/advisories, which ideally should list everything, or https://security-tracker.debian.org/tracker/source-package/flatpak-builder, which is usually fairly comprehensive for CVEs that are known to the public.

@swick, would you be able to get a CVE ID from Red Hat referencing the internal ticket? Probably best if you do it, via RH as CNA, because otherwise they'll allocate a duplicate CVE ID for their internal ticket and everyone will become confused.

@swick

swick commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator

I can, but it would be good to be able to just reference a published advisory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants